Version: App for Infrastructure 1.2.0
Splunk Enterprise 7.2
Comments: I had to manually create the em_metrics index. I did not see this as a step in the installation docs, but it didn't work until i did this. I'm wondering if the installation of the app didn't complete successfully?
Once it did start logging metrics, the Entity Name of the server being monitored was displaying wrong. The entity shows up as the name of the Http Event Collector (HEC) hostname and HEC port instead of the actual host name of the server being monitored. The host dimension also showed the HEC hostname and port instead of the host name of the server being monitored.
Other Splunk events coming from the server are displaying the correct host name. This only seems to be an issue for the App for Infrastructure data coming from the server.
Did i do something wrong when configuring the server? Is there a way to fix the Entity Name and Host dimension? I have tried rerunning the add data script but it did not fix anything.
... View more